Documentation PI Nexus+ Documentation

PI Nexus+ / Reference

Ports and Firewall

This reference lists every network connection PI Nexus+ makes, so you can request firewall rules before installation. Plan the Deployment in the Installation Guide shows the same connections as a diagram.

Overview

This reference lists every network connection PI Nexus+ makes, so you can request firewall rules before installation. Plan the Deployment in the Installation Guide shows the same connections as a diagram.

Inbound

ToPortFromUsed for
Web serverTCP 5139 (installer property IISPORT)Users' browsersThe PI Nexus+ site over HTTP
Web serverTCP 443 or your portUsers' browsersOnly if you add an HTTPS binding in IIS yourself (see Use HTTPS in the Installation Guide)

The scanner server accepts no inbound connections. The web server and the scanner server never connect to each other.

Outbound from both servers

On a single server, both columns are the same machine. On a split deployment, open each path from both servers unless the last column says otherwise.

ToPortNeeded whenUsed by
SQL Server hosting the PI Nexus+ databaseTCP 1433, or the instance's port; UDP 1434 for SQL Server Browser with a named instanceAlwaysBoth
PI Data Archive, every collective memberTCP 5450AlwaysBoth (the web server for Test, discovery and compression changes; the scanner for scans and runtime polls)
AF ServerTCP 5457AlwaysBoth
SQL Server hosting the PI Vision databaseTCP 1433, or the instance's portPI Vision inventory is usedBoth (the web server for Test)
SMTP serverTCP 25 by default; as set under Admin > NotificationsEmails are usedBoth (the web server for the test email)
Domain controllersStandard Active Directory portsAlways: Windows sign-in, account and group lookupsBoth
Identity server used by OpenID Connect targetsTCP 443, or the port the identity server publishes (AVEVA Identity Manager commonly uses 444)A PI Data Archive or AF Server target uses OpenID ConnectBoth

PI Vision inventory reads the PI Vision database only. The PI Vision web address is used for links in users' browsers and for host monitoring availability checks, not for scanning.

Outbound from the scanner server only

ToPortUsed for
Monitored hostsTCP 5985 (WinRM over HTTP)Host monitoring with the scanner service account
Monitored hosts outside the domainTCP 5986 (WinRM over HTTPS)Host monitoring with a credential profile
SQL Servers on monitored hostsTCP 1433 or the instance's portOptional SQL Server readings
Any hostAs configuredAvailability checks you add

All host monitoring ports are listed under Ports in Host Monitoring Reference.

Local ports on the PI Nexus+ servers

ItemDefaultChange with
IIS site bindinghttp, all addresses, port 5139IISPORT at installation, or IIS Manager afterwards
Start menu and desktop shortcutshttp://localhost:<IISPORT>/Follow IISPORT; the port is stored in HKLM\Software\Software Athlete\PI Nexus+\IisPort

Note: An upgrade or repair keeps your IIS bindings. Adding the web application again in a maintenance installation recreates the site's binding on IISPORT and removes others, such as an HTTPS binding you added.